        <?xml version="1.0" encoding="UTF-8"?>
        <rss version="2.0">
          <channel>
            <title>Security News Radar</title>
            <link>index.html</link>
            <description>Aktuelle CVEs, bekannte Exploits und wichtige Cybersecurity-Meldungen.</description>
            <language>de-DE</language>
            <lastBuildDate>Mon, 17 Aug 2026 15:02:19 +0000</lastBuildDate>
            <atom:link xmlns:atom="http://www.w3.org/2005/Atom" href="feed.xml" rel="self" type="application/rss+xml" />

            <item>
              <title>CVE-2025-62593: Ray-Project Ray - Ray-Project Ray Code Injection Vulnerability</title>
              <link>https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v ; https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-62593</link>
              <guid isPermaLink="false">cisa-kev:CVE-2025-62593</guid>
              <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
              <source>CISA KEV</source>
              <description>Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.</description>
            </item>

            <item>
              <title>Microsoft confirms GitHub is down worldwide</title>
              <link>https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/</link>
              <guid isPermaLink="false">bleepingcomputer security:https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/</guid>
              <pubDate>Mon, 17 Aug 2026 10:47:08 -0400</pubDate>
              <source>BleepingComputer Security</source>
              <description>GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. [...]</description>
            </item>

            <item>
              <title>CVE-2026-71567: In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables
 are injected without quoting them eit (openshift-metal3)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60193</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60193</guid>
              <pubDate>Mon, 17 Aug 2026 14:39:09 +0000</pubDate>
              <source>EUVD</source>
              <description>In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables
 are injected without quoting them either into command lines or into 
manifests. This mostly applies to the Image URL and BMC credentials 
(which are not verified by FakeFish).</description>
            </item>

            <item>
              <title>CVE-2026-59910: Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command (&#x27;OS Command In (Dell)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60195</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60195</guid>
              <pubDate>Mon, 17 Aug 2026 14:25:09 +0000</pubDate>
              <source>EUVD</source>
              <description>Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command (&#x27;OS Command Injection&#x27;) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.</description>
            </item>

            <item>
              <title>CVE-2026-71566: FakeFish handles incoming credentials by passing them down
 to scripts. This works for real hardware because in the end it&#x27;s up to 
the BMC  (openshift-metal3)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60205</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60205</guid>
              <pubDate>Mon, 17 Aug 2026 14:22:16 +0000</pubDate>
              <source>EUVD</source>
              <description>FakeFish handles incoming credentials by passing them down
 to scripts. This works for real hardware because in the end it&#x27;s up to 
the BMC to validate them. However, KubeVirt relies on a KUBECONFIG file 
mounted to the container and completely ignores the credentials. This allows any user of the cluster to control VMs of the 
user that created fakefish, power them on and off, and mount arbitrary CD
 images to them.</description>
            </item>

            <item>
              <title>CVE-2026-59910: Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command (&#x27;OS Command In</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-59910</link>
              <guid isPermaLink="false">nvd:CVE-2026-59910</guid>
              <pubDate>Mon, 17 Aug 2026 14:20:21 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command (&#x27;OS Command Injection&#x27;) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.</description>
            </item>

            <item>
              <title>CVE-2026-59909: Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could po</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-59909</link>
              <guid isPermaLink="false">nvd:CVE-2026-59909</guid>
              <pubDate>Mon, 17 Aug 2026 14:20:21 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.</description>
            </item>

            <item>
              <title>CVE-2026-56686: Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command (&#x27;OS Command In</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-56686</link>
              <guid isPermaLink="false">nvd:CVE-2026-56686</guid>
              <pubDate>Mon, 17 Aug 2026 14:20:21 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command (&#x27;OS Command Injection&#x27;) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.</description>
            </item>

            <item>
              <title>CVE-2026-56685: Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command (&#x27;OS Command In</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-56685</link>
              <guid isPermaLink="false">nvd:CVE-2026-56685</guid>
              <pubDate>Mon, 17 Aug 2026 14:20:21 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command (&#x27;OS Command Injection&#x27;) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.</description>
            </item>

            <item>
              <title>CVE-2026-56090: Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with lo</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-56090</link>
              <guid isPermaLink="false">nvd:CVE-2026-56090</guid>
              <pubDate>Mon, 17 Aug 2026 14:20:21 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.</description>
            </item>

            <item>
              <title>CVE-2026-19693: extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry&#x27;s own final path component,</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-19693</link>
              <guid isPermaLink="false">nvd:CVE-2026-19693</guid>
              <pubDate>Mon, 17 Aug 2026 14:20:20 +0000</pubDate>
              <source>NVD CVE</source>
              <description>extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry&#x27;s own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.</description>
            </item>

            <item>
              <title>CVE-2026-16471: Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by A</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-16471</link>
              <guid isPermaLink="false">nvd:CVE-2026-16471</guid>
              <pubDate>Mon, 17 Aug 2026 14:20:20 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Sonlogger: from v6.6.6 before 6.7.4.8.</description>
            </item>

            <item>
              <title>CVE-2026-16139: In Progress ShareFile Storage Zones Controller versions &lt;= 5.12.5 and &lt;= 6.0.2, an authenticated zone administrator can exploit improper val</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-16139</link>
              <guid isPermaLink="false">nvd:CVE-2026-16139</guid>
              <pubDate>Mon, 17 Aug 2026 14:20:19 +0000</pubDate>
              <source>NVD CVE</source>
              <description>In Progress ShareFile Storage Zones Controller versions &lt;= 5.12.5 and &lt;= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.</description>
            </item>

            <item>
              <title>CVE-2026-16138: In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a use</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-16138</link>
              <guid isPermaLink="false">nvd:CVE-2026-16138</guid>
              <pubDate>Mon, 17 Aug 2026 14:20:19 +0000</pubDate>
              <source>NVD CVE</source>
              <description>In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.</description>
            </item>

            <item>
              <title>CVE-2026-16137: In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resum</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-16137</link>
              <guid isPermaLink="false">nvd:CVE-2026-16137</guid>
              <pubDate>Mon, 17 Aug 2026 14:20:19 +0000</pubDate>
              <source>NVD CVE</source>
              <description>In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application&#x27;s service account. This may result in the execution of attacker-supplied code.</description>
            </item>

            <item>
              <title>CVE-2026-15218: A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-15218</link>
              <guid isPermaLink="false">nvd:CVE-2026-15218</guid>
              <pubDate>Mon, 17 Aug 2026 14:20:19 +0000</pubDate>
              <source>NVD CVE</source>
              <description>A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution vulnerability or by creating a malicious pod in the same namespace, could exploit these excessive permissions. This could lead to full cluster administrator privileges through the creation of new ClusterRoleBindings or the disclosure of sensitive information by accessing all secrets across the cluster.</description>
            </item>

            <item>
              <title>CVE-2023-6931: A heap out-of-bounds write vulnerability in the Linux kernel&#x27;s Performance Events system component can be exploited to achieve local privile (Linux)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2023-59129</link>
              <guid isPermaLink="false">euvd:EUVD-2023-59129</guid>
              <pubDate>Mon, 17 Aug 2026 14:11:22 +0000</pubDate>
              <source>EUVD</source>
              <description>A heap out-of-bounds write vulnerability in the Linux kernel&#x27;s Performance Events system component can be exploited to achieve local privilege escalation.



A perf_event&#x27;s read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().



We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.</description>
            </item>

            <item>
              <title>CVE-2026-59909: Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could po (Dell)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60202</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60202</guid>
              <pubDate>Mon, 17 Aug 2026 13:48:56 +0000</pubDate>
              <source>EUVD</source>
              <description>Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.</description>
            </item>

            <item>
              <title>CVE-2026-56090: Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with lo (Dell)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60201</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60201</guid>
              <pubDate>Mon, 17 Aug 2026 13:44:51 +0000</pubDate>
              <source>EUVD</source>
              <description>Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.</description>
            </item>

            <item>
              <title>CVE-2026-56685: Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command (&#x27;OS Command In (Dell)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60200</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60200</guid>
              <pubDate>Mon, 17 Aug 2026 13:40:04 +0000</pubDate>
              <source>EUVD</source>
              <description>Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command (&#x27;OS Command Injection&#x27;) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.</description>
            </item>

            <item>
              <title>CVE-2026-15218: A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60199</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60199</guid>
              <pubDate>Mon, 17 Aug 2026 13:39:18 +0000</pubDate>
              <source>EUVD</source>
              <description>A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution vulnerability or by creating a malicious pod in the same namespace, could exploit these excessive permissions. This could lead to full cluster administrator privileges through the creation of new ClusterRoleBindings or the disclosure of sensitive information by accessing all secrets across the cluster.</description>
            </item>

            <item>
              <title>CVE-2026-16137: In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resum (Progress)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60198</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60198</guid>
              <pubDate>Mon, 17 Aug 2026 13:32:45 +0000</pubDate>
              <source>EUVD</source>
              <description>In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application&#x27;s service account. This may result in the execution of attacker-supplied code.</description>
            </item>

            <item>
              <title>CVE-2026-16138: In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a use (Progress)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60197</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60197</guid>
              <pubDate>Mon, 17 Aug 2026 13:32:01 +0000</pubDate>
              <source>EUVD</source>
              <description>In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.</description>
            </item>

            <item>
              <title>CVE-2025-62593: Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE  (ray-project)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2025-199754</link>
              <guid isPermaLink="false">euvd:EUVD-2025-199754</guid>
              <pubDate>Mon, 17 Aug 2026 13:31:33 +0000</pubDate>
              <source>EUVD</source>
              <description>Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string &quot;Mozilla&quot; as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.</description>
            </item>

            <item>
              <title>CVE-2026-16139: In Progress ShareFile Storage Zones Controller versions &lt;= 5.12.5 and &lt;= 6.0.2, an authenticated zone administrator can exploit improper val (Progress)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60196</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60196</guid>
              <pubDate>Mon, 17 Aug 2026 13:31:14 +0000</pubDate>
              <source>EUVD</source>
              <description>In Progress ShareFile Storage Zones Controller versions &lt;= 5.12.5 and &lt;= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.</description>
            </item>

            <item>
              <title>CVE-2026-19693: extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry&#x27;s own final path component, (max-mapper)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60194</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60194</guid>
              <pubDate>Mon, 17 Aug 2026 13:30:22 +0000</pubDate>
              <source>EUVD</source>
              <description>extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry&#x27;s own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.</description>
            </item>

            <item>
              <title>CVE-2026-56686: Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command (&#x27;OS Command In (Dell)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60177</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60177</guid>
              <pubDate>Mon, 17 Aug 2026 13:26:44 +0000</pubDate>
              <source>EUVD</source>
              <description>Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command (&#x27;OS Command Injection&#x27;) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.</description>
            </item>

            <item>
              <title>⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More</title>
              <link>https://thehackernews.com/2026/08/weekly-recap-vmware-exploits-windows-0.html</link>
              <guid isPermaLink="false">the hacker news:https://thehackernews.com/2026/08/weekly-recap-vmware-exploits-windows-0.html</guid>
              <pubDate>Mon, 17 Aug 2026 18:53:51 +0530</pubDate>
              <source>The Hacker News</source>
              <description>The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a</description>
            </item>

            <item>
              <title>CVE-2026-75002: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information d</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-75002</link>
              <guid isPermaLink="false">nvd:CVE-2026-75002</guid>
              <pubDate>Mon, 17 Aug 2026 13:16:54 +0000</pubDate>
              <source>NVD CVE</source>
              <description>In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.</description>
            </item>

            <item>
              <title>CVE-2026-74998: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which m</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-74998</link>
              <guid isPermaLink="false">nvd:CVE-2026-74998</guid>
              <pubDate>Mon, 17 Aug 2026 13:16:54 +0000</pubDate>
              <source>NVD CVE</source>
              <description>In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.</description>
            </item>

            <item>
              <title>CVE-2026-74997: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-74997</link>
              <guid isPermaLink="false">nvd:CVE-2026-74997</guid>
              <pubDate>Mon, 17 Aug 2026 13:16:54 +0000</pubDate>
              <source>NVD CVE</source>
              <description>In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.</description>
            </item>

            <item>
              <title>CVE-2026-16467: Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-16467</link>
              <guid isPermaLink="false">nvd:CVE-2026-16467</guid>
              <pubDate>Mon, 17 Aug 2026 13:16:50 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Fortilogger: before 6.1.5.9.</description>
            </item>

            <item>
              <title>CVE-2026-14564: Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows </title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-14564</link>
              <guid isPermaLink="false">nvd:CVE-2026-14564</guid>
              <pubDate>Mon, 17 Aug 2026 13:16:50 +0000</pubDate>
              <source>NVD CVE</source>
              <description>Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data.

This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.</description>
            </item>

            <item>
              <title>CVE-2026-16471: Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by A (Dolusoft Software Technologies)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60176</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60176</guid>
              <pubDate>Mon, 17 Aug 2026 13:15:15 +0000</pubDate>
              <source>EUVD</source>
              <description>Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Sonlogger: from v6.6.6 before 6.7.4.8.</description>
            </item>

            <item>
              <title>CVE-2026-16467: Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by (Dolusoft Software Technologies)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60173</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60173</guid>
              <pubDate>Mon, 17 Aug 2026 12:59:01 +0000</pubDate>
              <source>EUVD</source>
              <description>Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Fortilogger: before 6.1.5.9.</description>
            </item>

            <item>
              <title>CVE-2026-75002: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information d (Roundcube)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60168</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60168</guid>
              <pubDate>Mon, 17 Aug 2026 12:48:41 +0000</pubDate>
              <source>EUVD</source>
              <description>In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.</description>
            </item>

            <item>
              <title>CVE-2026-73634: Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy (Apache Software Foundation)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-59603</link>
              <guid isPermaLink="false">euvd:EUVD-2026-59603</guid>
              <pubDate>Mon, 17 Aug 2026 12:44:54 +0000</pubDate>
              <source>EUVD</source>
              <description>Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. Such endpoints are ordinarily reachable without authentication. The core distribution maps no such endpoint by default; applications that do not collect violation reports are not affected.

This issue affects Apache Struts: from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1.

Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.</description>
            </item>

            <item>
              <title>CVE-2026-73635: Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for (Apache Software Foundation)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-59604</link>
              <guid isPermaLink="false">euvd:EUVD-2026-59604</guid>
              <pubDate>Mon, 17 Aug 2026 12:43:26 +0000</pubDate>
              <source>EUVD</source>
              <description>Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework&#x27;s internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. Applications that configure a fixed locale are not affected.

This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1.

Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.</description>
            </item>

            <item>
              <title>CVE-2026-74998: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which m (Roundcube)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60165</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60165</guid>
              <pubDate>Mon, 17 Aug 2026 12:40:29 +0000</pubDate>
              <source>EUVD</source>
              <description>In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.</description>
            </item>

            <item>
              <title>CVE-2026-74997: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution (Roundcube)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60164</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60164</guid>
              <pubDate>Mon, 17 Aug 2026 12:37:45 +0000</pubDate>
              <source>EUVD</source>
              <description>In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.</description>
            </item>

            <item>
              <title>Windows Server 2022 reaches end of mainstream support in 60 days</title>
              <link>https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-in-60-days/</link>
              <guid isPermaLink="false">bleepingcomputer security:https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-in-60-days/</guid>
              <pubDate>Mon, 17 Aug 2026 08:33:11 -0400</pubDate>
              <source>BleepingComputer Security</source>
              <description>Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]</description>
            </item>

            <item>
              <title>CVE-2026-40126: OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker  (OutSystems)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60159</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60159</guid>
              <pubDate>Mon, 17 Aug 2026 12:32:27 +0000</pubDate>
              <source>EUVD</source>
              <description>OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server.

This issue was fixed in OutSystems Service Center version 11.41.2</description>
            </item>

            <item>
              <title>CVE-2026-14564: Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows  (Innotim Software Telecommunications and Consulting Trade Ltd. Co.)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60161</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60161</guid>
              <pubDate>Mon, 17 Aug 2026 12:26:34 +0000</pubDate>
              <source>EUVD</source>
              <description>Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data.

This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.</description>
            </item>

            <item>
              <title>CVE-2026-74843: A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /et</title>
              <link>https://nvd.nist.gov/vuln/detail/CVE-2026-74843</link>
              <guid isPermaLink="false">nvd:CVE-2026-74843</guid>
              <pubDate>Mon, 17 Aug 2026 12:18:58 +0000</pubDate>
              <source>NVD CVE</source>
              <description>A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component Export Pingortrace CGI. Executing a manipulation of the argument HTTP_COOKIE can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.</description>
            </item>

            <item>
              <title>CVE-2026-18674: On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled (Kong Inc.)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-60160</link>
              <guid isPermaLink="false">euvd:EUVD-2026-60160</guid>
              <pubDate>Mon, 17 Aug 2026 12:08:11 +0000</pubDate>
              <source>EUVD</source>
              <description>On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global control plane store and re-distribute those resources as belonging to another zone.



The result is a cross-zone isolation bypass: the holder of a single enrolled zone&#x27;s credential can inject, attribute, and overwrite resources in another zone&#x27;s namespace mesh-wide.




The root cause lives in Kuma&#x27;s open-source KDS sync code, which Kong Mesh&#x27;s control plane is built on.</description>
            </item>

            <item>
              <title>CVE-2026-31938: jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function a (parallax)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-12755</link>
              <guid isPermaLink="false">euvd:EUVD-2026-12755</guid>
              <pubDate>Mon, 17 Aug 2026 12:05:18 +0000</pubDate>
              <source>EUVD</source>
              <description>jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the created PDF is opened in. The vulnerability can be exploited in the following scenario: the attacker provides values for the output options, for example via a web interface. These values are then passed unsanitized (automatically or semi-automatically) to the attack victim. The victim creates and opens a PDF with the attack vector using one of the vulnerable method overloads inside their browser. The attacker can thus inject scripts that run in the victims browser context and can extract or modify secrets from this context. The vulnerability has been fixed in jspdf@4.2.1. As a workaround, sanitize user input before passing it to the output method.</description>
            </item>

            <item>
              <title>CVE-2025-68428: jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the  (parallax)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-0847</link>
              <guid isPermaLink="false">euvd:EUVD-2026-0847</guid>
              <pubDate>Mon, 17 Aug 2026 12:05:14 +0000</pubDate>
              <source>EUVD</source>
              <description>jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsanitized paths to the loadFile method, a user can retrieve file contents of arbitrary files in the local file system the node process is running in. The file contents are included verbatim in the generated PDFs. Other affected methods are `addImage`, `html`, and `addFont`. Only the node.js builds of the library are affected, namely the `dist/jspdf.node.js` and `dist/jspdf.node.min.js` files. The vulnerability has been fixed in jsPDF@4.0.0. This version restricts file system access per default. This semver-major update does not introduce other breaking changes. Some workarounds areavailable. With recent node versions, jsPDF recommends using the `--permission` flag in production. The feature was introduced experimentally in v20.0.0 and is stable since v22.13.0/v23.5.0/v24.0.0. For older node versions, sanitize user-provided paths before passing them to jsPDF.</description>
            </item>

            <item>
              <title>CVE-2026-47162: Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHi (vim)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-36281</link>
              <guid isPermaLink="false">euvd:EUVD-2026-36281</guid>
              <pubDate>Mon, 17 Aug 2026 12:05:13 +0000</pubDate>
              <source>EUVD</source>
              <description>Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495.</description>
            </item>

            <item>
              <title>CVE-2026-39364: Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be bloc (vitejs)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-19873</link>
              <guid isPermaLink="false">euvd:EUVD-2026-19873</guid>
              <pubDate>Mon, 17 Aug 2026 12:05:13 +0000</pubDate>
              <source>EUVD</source>
              <description>Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&amp;raw, or ?import&amp;url&amp;inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.</description>
            </item>

            <item>
              <title>CVE-2026-32141: flatted is a circular JSON parser. Prior to 3.4.0, flatted&#x27;s parse() function uses a recursive revive() phase to resolve circular references (WebReflection)</title>
              <link>https://euvd.enisa.europa.eu/enisa/EUVD-2026-11653</link>
              <guid isPermaLink="false">euvd:EUVD-2026-11653</guid>
              <pubDate>Mon, 17 Aug 2026 12:05:13 +0000</pubDate>
              <source>EUVD</source>
              <description>flatted is a circular JSON parser. Prior to 3.4.0, flatted&#x27;s parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the Node.js process. This vulnerability is fixed in 3.4.0.</description>
            </item>

          </channel>
        </rss>
